
EC-CouncilDevSecOps Essentials
Domain 3Objective 3
Continuous Testing Tools DSE Practice Questions (Page 2)
Part of the DevSecOps Toolchain domain, which makes up ~19% of our current practice bank. EC-Council does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 2–3 from this objective — we provide 58 practice questions to prepare you well beyond it. (estimate)
58questions here
12free pages
10concepts
Questions 6–10
- 6
A company is planning to adopt a shift-left testing strategy. They currently rely on DAST scans in production and want to move security testing earlier. They have limited budget and want to get the most value for their investment. Which combination of actions would best achieve shift-left testing?
Select an answer first - 7
A team wants to identify security vulnerabilities in their Java application's source code before the code is compiled or deployed. They want the scan to run quickly and provide line-level findings to developers. Which type of tool should they integrate into their CI pipeline?
Select an answer first - 8
What is a key advantage of IAST over traditional SAST and DAST?
Select an answer first - 9
In a CI/CD pipeline, when are automated tests typically triggered?
Select an answer first - 10
A security team is receiving hundreds of SAST findings every week, but developers are only fixing a small fraction. Analysis shows that many findings are duplicates across modules or are false positives. The team wants to increase the remediation rate without overwhelming developers. Which approach is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “DSE” is a trademark of its owner, used for identification only.